𝗜𝗠𝗣𝗢𝗥𝗧𝗔𝗡𝗧 𝗨𝗣𝗗𝗔𝗧𝗘𝗦: The withdrawal plan will be announced by September 26th, 4:00 AM UTC. We appreciate your patience on this matter.
Based on the latest onchain tracing and classification of transactions, assets equivalent to approximately $387.5 million were transferred to attacker-controlled addresses across multiple networks.
The revised figure reflects a more complete accounting of transfers that occurred during the incident, adding affected assets on Zcash and TRON that were not included in the initial estimate. It does not reflect further unauthorized transfers.
The incident remains contained and no further unauthorized transfers are possible.
The incident involved assets across Ethereum and several EVM networks, XRP Ledger, Zcash and TRON.
The primary attacker-controlled receiving addresses identified to date are:
→ EVM: 0x770b10b273fc44fe9197d6bf20f145c2e98463ee
→ XRP: rwNhefsz1UQEusxhCvHip3RANinWi4CTck
→ ZEC: t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG
→ TRON: TBWNguTTgezw9dVorX441C6nDrZpRxYwKD
The confirmed affected assets include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX.
Our investigation and tracing efforts remain ongoing.
The figures above reflect information confirmed at the time of publication and may be updated as additional transactions are classified and traced.
The incident remains contained, with no further unauthorized transfers since the incident was contained, and the investigation with Mandiant and SlowMist remains ongoing
Withdrawals remain temporarily paused while additional security checks and remediation are underway.
Bitget will continue to provide verified updates on the investigation, asset recovery, withdrawal restoration and the User Protection Fund through its official channels.
𝘍𝘰𝘳 𝘪𝘯𝘧𝘰𝘳𝘮𝘢𝘵𝘪𝘰𝘯𝘢𝘭 𝘱𝘶𝘳𝘱𝘰𝘴𝘦𝘴 𝘰𝘯𝘭𝘺.
At 18:31 UTC on September 24, 2026, Bitget’s security systems identified unauthorized transfers involving a limited number of hot wallets.
Our security team immediately activated emergency response procedures and began a full investigation.
Based on our current assessment, approximately $351.6 million in assets were affected. Bitget’s cold wallets and the overwhelming majority of platform assets remain secure and unaffected.
Most importantly, user funds remain protected.
The incident falls within the coverage of Bitget’s User Protection Fund, which currently holds more than $464 million.
Customer account balances remain accurate, and deposits and trading continue to operate normally.
As a precaution, withdrawals have been temporarily suspended while our teams complete a comprehensive security review.
We have identified and flagged the relevant transfer addresses and have formally engaged law enforcement agencies and leading on-chain security partners.
We are working around the clock to restore withdrawal services as soon as it is safe to do so.
Bitget will provide further updates through our official channels.
We will not speculate on the attack vector while the investigation remains ongoing. Our focus is on protecting users, securing all systems, and delivering complete transparency throughout this process.